PT-2023-20673 · Authentik · Authentik

Fuomag9

·

Publicado

2023-03-04

·

Atualizado

2026-04-16

·

CVE-2023-26481

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions authentik versions prior to 2022.12.2 authentik versions prior to 2023.1.3 authentik versions prior to 2023.2.3
Description The issue arises from an insufficient access check in the recovery flow, allowing a created recovery link to be used for setting the password of any arbitrary user. This is possible if a recovery flow with both an Identification and an Email stage exists. The attack requires an administrator to create or send a recovery link to the attacker, who can then exploit the improper token validation to change passwords. Custom recovery flows are recommended to include a policy that skips the identification stage when the flow is restored, by checking request.context['is restored'].
Recommendations For versions prior to 2022.12.2, update to version 2022.12.2 or later. For versions prior to 2023.1.3, update to version 2023.1.3 or later. For versions prior to 2023.2.3, update to version 2023.2.3 or later. As a temporary workaround, consider adding a policy to custom recovery flows that checks if the flow is restored and skips the identification stage by verifying request.context['is restored'].

Exploit

Correção

Insufficient Verification of Data Authenticity

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-AUTHENTIK-2023-26481
CVE-2023-26481
GHSA-3XF5-PQVF-RQQ3

Produtos afetados

Authentik